查看: 4744|回复: 13
收起左侧

[病毒样本] 微点发现2支新的木马软件

[复制链接]
Nblock
发表于 2007-10-22 12:51:28 | 显示全部楼层 |阅读模式
PCIBUS.SYS  
Norman Virus Control :

Found Sandbox: W32/Malware; [ General information ]

* **Locates window "ȰЇ̡ʾ [class NULL]" on desktop.

[ Changes to filesystem ]
* Deletes file "C:\SAMPLE.EXE" .
* Creates file C:\WINDOWS\SYSTEM32\Com\comrepl32.exe.
* Creates file C:\WINDOWS\SYSTEM32\taimpo.txt.
* Creates file C:\WINDOWS\SYSTEM32\config\AppEventw.cfg.
* Deletes file C:\WINDOWS\SYSTEM32\taimpo.txt.
* Creates file C:\WINDOWS\SYSTEM32\utility.hiv.
* Deletes file C:\WINDOWS\SYSTEM32\utility.hiv.

[ Network services ]
* Downloads file from http://www.9669093.com/elf_listo.txt as C:\WINDOWS\SYSTEM32\taimpo.txt.
* Connects to "www.9669093.com" on port 80 (TCP).
* Opens URL: www.9669093.com/elf_listo.txt.
* Connects to "FAKE" on port 4444 (TCP).

[ Security issues ]
* Possible backdoor functionality [UNKNOWN] port 4444.

[ Process/window information ]
* Creates a mutex tls.
* Enumerates running processes.
* Enumerates running processes several parses....


[ 本帖最后由 Nblock 于 2007-10-22 13:01 编辑 ]

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
红心王子
发表于 2007-10-22 12:53:11 | 显示全部楼层
cc.rar 小a没报

2007-10-22        12:52:45        1193028765        Administrator        268        Sign of "Win32:Hupigon-DKZ [Trj]" has been found in "D:\Downloads\1.rar\1.exe" file.
Nblock
 楼主| 发表于 2007-10-22 12:57:41 | 显示全部楼层
cc卡巴扫描不报
chow2006
发表于 2007-10-22 13:03:27 | 显示全部楼层
原帖由 <i>红心王子</i> 于 2007-10-22 12:53 发表 <a href="http://bbs.kafan.cn/redirect.php?goto=findpost&pid=1933081&ptid=146841" target="_blank"><img src="http://bbs.kafan.cn/images/common/back.gif" border="0" onclick="zoom(this)" onload="attachimg(this, 'load')" alt="" /></a><br />
cc.rar 小a没报<br />
<br />
2007-10-22        12:52:45        1193028765        Administrator        268        Sign of "Win32:Hupigon-DKZ " has been found in "D:\Downloads\1.rar\1.exe" file.
<br />

刚好相反,费尔报了CC.rar,19号的病毒库

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
风野胤
发表于 2007-10-22 13:03:44 | 显示全部楼层
eav报壳

R:\1.rar » RAR » 1.exe - Win32/Packed.PEArmor.Gen application
mofunzone
发表于 2007-10-22 13:05:37 | 显示全部楼层
Starting the file scan:

Begin scan in 'C:\Users\morgan\Documents\CC.rar'
C:\Users\morgan\Documents\
  CC.rar
    [0] Archive type: RAR
    --> CC.EXE
        [DETECTION] Is the Trojan horse TR/Dldr.Agent.45056
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
Begin scan in 'C:\Users\morgan\Documents\1.rar'
C:\Users\morgan\Documents\
  1.rar
    [0] Archive type: RAR
    --> 1.exe
        [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Hupigon.Gen Backdoor server programs
        [WARNING]   Infected files in archives cannot be repaired!
        [WARNING]   The file was ignored!
The EQs
发表于 2007-10-22 13:05:44 | 显示全部楼层
C:\Documents and Settings\Don johnson\桌面\1.rar &raquo; RAR &raquo; 1.exe - Win32/Packed.PEArmor.Gen application
C:\Documents and Settings\Don johnson\桌面\CC.rar &raquo; RAR &raquo; CC.EXE - a variant of Win32/Jalous worm
saber123
发表于 2007-10-22 13:08:19 | 显示全部楼层
CC.rar检测结果:
扫描结果
扫描结果 :  51%的杀软(18/35)报告发现病毒
时间 :  2007/10/22 13:02:27 (CST)
软件名称引擎版本病毒库版本病毒库时间扫描结果时间
a-squared3.0.0.1262007.10.212007-10-21-
8.456
安博士V32007.10.20.002007.10.202007-10-20-
1.441
AntiVir7.6.0.277.0.0.1142007-10-21TR/Dldr.Agent.45056
2.506
Arcavir1.0.42007102114552007-10-21Heur.Win32.I
1.896
AVAST1.0.8000783-02007-10-21-
3.439
AVG7.5.49.442269.15.5/10842007-10-21-
2.114
BitDefender7.60825.9344597.154162007-10-22MemScan:Trojan.Downloader.Agent.YQS
3.963
CA (VET)8.4.0.2431.2.52252007-10-20-
2.807
ClamAV 0.91.245582007-10-22PUA.Packed.UPack-2
0.007
Comodo2.112.0.0.3202007-10-21-
6.713
Dr.WEB4.332007.10.212007-10-21-
8.865
ewido4.0.0.22007.10.212007-10-21-
5.703
F-PROT4.4.0.50200710182007-10-18Possible W32/Heuristic-162!Eldorado (damaged, not disinfectable)
3.180
F-SECURE5.51.61002007.10.22.012007-10-22-
5.145
飞塔2.81-3.118.2642007-10-21Suspicious
2.705
ViRobot200710192007.10.192007-10-19-
4.500
IKARUST3.1.1.122007.10.21.696962007-10-21Trojan-Downloader.Win32.Zlob.and
5.598
江民杀毒10.00.6502007.10.212007-10-21Trojan/Agent.kxp
5.090
卡巴斯基5.5.102007.10.222007-10-22-
8.230
金山毒霸2007.6.20.2492007.10.202007-10-20-
14.251
迈克菲5.2.0051452007-10-19New Malware.aj
2.389
MKS_VIR2.012007.10.202007-10-20Heur.Win32
2.196
NOD322.70.1026052007-10-22-
0.003
NORMAN5.91.085.902007-10-19W32/Suspicious_U.gen
3.480
熊猫卫士9.04.03.00012007.10.212007-10-21-
4.836
趋势8.500-10014.788.012007-10-21TROJ_DLOADER.RTH
0.038
PrevxV2200710222007-10-22-
36.157
QuickHeal9.002007.10.202007-10-20Suspicious - DNAScan
7.649
瑞星19.019.45.62.002007-10-21-
3.541
SOPHOS2.49.14.212007-10-22Mal/Packer
6.481
赛门铁克1.3.0.2420071021.0052007-10-21-
7.560
nProtect2007-10-19.009833652007-10-19BehavesLike:Win32.ExplorerHijack
26.667
The Hacker6.2.9v001032007-10-21W32/Behav-Heuristic-060
0.765
VBA323.12.2.420071021.10472007-10-21Embedded.Worm.Win32.Downloader.a (suspicious)
1.799
VirusBuster4.3.19:99.112.2/11.02007-10-21Packed/Upack
1.026
注意: 就算报告发现病毒,也可能是杀软误报,请根据查毒结果自行判断

1.RAR检测结果:
扫描结果
扫描结果 :  46%的杀软(16/35)报告发现病毒
时间 :  2007/10/22 13:12:28 (CST)
软件名称引擎版本
病毒库版本
病毒库时间
扫描结果
时间
a-squared3.0.0.1262007.10.212007-10-21-
7.471
AntiVir7.6.0.277.0.0.1142007-10-21BDS/Hupigon.Gen
2.047
Arcavir1.0.42007102114552007-10-21-
1.365
AVAST1.0.8000783-02007-10-21Win32:Hupigon-DKZ [Trj]
3.061
AVG7.5.49.442269.15.5/10842007-10-21Packed.PE-Armor
1.668
BitDefender7.60825.9344597.154162007-10-22Packer.PEArmor.A
4.029
CA (VET)8.4.0.2431.2.52252007-10-20-
3.640
ClamAV 0.91.245582007-10-22Trojan.Graybird-16
0.121
Comodo2.112.0.0.3202007-10-21-
2.233
Dr.WEB4.332007.10.212007-10-21-
6.538
ewido4.0.0.22007.10.212007-10-21-
3.065
F-PROT4.4.0.50200710182007-10-18Possible W32/Threat-HLLPEM-based!Maximus
1.553
F-SECURE5.51.61002007.10.22.012007-10-22-
2.714
IKARUST3.1.1.122007.10.21.696962007-10-21Backdoor.Win32.Hupigon.cda
1.658
MKS_VIR2.012007.10.202007-10-20-
2.261
NOD322.70.1026052007-10-22-
0.003
NORMAN5.91.085.902007-10-19W32/Kenfa.D
3.356
nProtect2007-10-19.009833652007-10-19Packer.PEArmor.A
14.191
PrevxV2200710222007-10-22-
17.512
QuickHeal9.002007.10.202007-10-20-
3.301
SOPHOS2.49.14.212007-10-22Mal/GrayBird
3.216
The Hacker6.2.9v001032007-10-21-
0.775
VBA323.12.2.420071021.10472007-10-21-
2.000
ViRobot200710192007.10.192007-10-19-
0.509
VirusBuster4.3.19:99.112.2/11.02007-10-21Packed/PE-Armor
3.456
卡巴斯基5.5.102007.10.222007-10-22-
4.301
安博士V32007.10.20.002007.10.202007-10-20-
1.314
江民杀毒10.00.6502007.10.212007-10-21-
1.341
熊猫卫士9.04.03.00012007.10.212007-10-21-
5.115
瑞星19.019.45.62.002007-10-21Backdoor.Gpigeon.GEN
2.137
赛门铁克1.3.0.2420071021.0052007-10-21-
0.231
趋势8.500-10014.788.012007-10-21Possible_HPGN-1
0.039
迈克菲5.2.0051452007-10-19BackDoor-AWQ.b
0.876
金山毒霸2007.6.20.2492007.10.202007-10-20Win32.Hack.Huigezi.cz
1.205
飞塔2.81-3.118.2642007-10-21Suspicious
0.628
注意: 就算报告发现病毒,也可能是杀软误报,请根据查毒结果自行判断

[ 本帖最后由 saber123 于 2007-10-22 13:15 编辑 ]
capsshift
发表于 2007-10-22 13:32:46 | 显示全部楼层
1.exe,瑞星报已知。
CC。EXE,运行后,瑞星主防拦截信息与微点相同。
残缺的唯美
发表于 2007-10-22 14:34:00 | 显示全部楼层
The requested URL http://bbs.kafan.cn/attachment.php?aid=142381 is infected with Heur.Trojan.Generic virus
deleted: virus Heur.Backdoor.Generic        File: C:\Users\Administrator\Desktop\1.rar/1.exe//PE-Armor
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-20 00:57 , Processed in 0.133796 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表